Skip to content
COOEY

FAIL › dossier

Network Attached Storage (NAS)

PRODUCT

· dossier confidence 20%

QNAP is a NAS vendor with a documented history of critical vulnerabilities in File Station and HBS 3 services that were actively exploited in ransomware attacks.

PROFILE
CategoryNASWhat they doQNAP develops and sells network-attached storage (NAS) devices and solutions for desktop, notebook, and enterprise environments. Websitehttps://www.qnap.com ↗
SECURITY POSTURE

QNAP has a history of critical vulnerabilities in its File Station and HBS 3 services, including RCE and XSS flaws that were actively exploited in ransomware attacks.

Notable failures
  • CVE-2018-19949: Critical RCE in File Station
  • CVE-2018-19953: Critical XSS in File Station
  • CVE-2018-19943: Critical XSS in File Station
  • CVE-2021-28799: Critical RCE in HBS 3
Patterns: Repeated critical RCE vulnerabilities in File Station; XSS vulnerabilities enabling ransomware attacks; Improper authorization in HBS 3 service
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2022-05-24 CVE-2018-19949 critical QNAP NAS File Station suffered a critical command injection flaw that allowed remote attackers to execute arbitrary commands, directly enabling ransomware attacks.
2022-05-24 CVE-2018-19953 critical QNAP NAS File Station XSS vulnerability allowed remote attackers to inject malicious code, linked to ransomware attacks.
2022-05-24 CVE-2018-19943 critical QNAP NAS devices were vulnerable to cross-site scripting, exploited in the wild, and linked to ransomware activity.
2022-03-31 CVE-2021-28799 critical QNAP NAS devices with HBS 3 allowed unauthorized remote logins due to an improper authorization vulnerability, actively exploited in ransomware attacks.
Open questions: Current patch status of affected QNAP devices · Recent security posture improvements post-2022
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:45:13.720422+00:00